RU2230438C2

Method for generating encryption-decryption key

Abstract

FIELD: electrical communications and computer engineering; cryptographic data conversion. SUBSTANCE: method involves generation of two binary vectors of a and p numbers, p being prime number and p>=2n-1, where n is key length in bits; transmission of binary vectors of numbers a and p to each network user over unprotected communication channel of network; independent generation of private keys by each of network users and generation of public keys by network users by converting binary vectors of private key and a and p numbers; transmission of public keys over unprotected communication channel to all other network users and generation of common private key by network user for communication with other network user by converting binary vectors of own private key and public key of other network user. EFFECT: enhanced speed of encryption-decryption key generation process; enhanced encryption speed. 1 cl, 1 dwg

Term

No projected expiry on record.

  1. Priority and filed
  2. Granted
  3. Today

1 claim: 1 independent, 0 dependent

  1. 1
    The method for forming the encryption key-decryption based on generating two binary vectors of a and p, and 1 <a <2n, and p is a prime number and r≥ 2n-1, where n - the key length in bits, transmission over an insecure communications channel Binary vectors of a and p each network user, generating network users independently of the first secret key xA1, ..., xB1, xA1 wherein - the first secret key of the user A, 1 <xA1 <2n;hV1 - the first in the user's private key, 1 <xV1 <2n and the formation of the first users of the network of public keys by converting binary vectors of the first secret key and the numbers a and p uA1≡ (mod p), ..., uV1≡ (mod p) where uA1 - the first public key of the user A;uV1 - the first public key of user B transmission over an insecure communication channel first public key to all the other users on the network and the formation of the user network to communicate with another user of the first shared secret subkey K1 by converting binary vectors his first secret key and the first public key of another user on the network Способ формирования ключа шифрования-дешифрования, основанный на генерировании двух двоичных векторов чисел а и р, причем 1<а<2n, а р является простым числом и р≥ 2n-1, где n - длина ключа в битах, передачи по незащищенному каналу связи двоичных векторов чисел а и р каждому пользователю сети, генерировании пользователями сети независимо друг от друга первых секретных ключей xA1,..., xB1, где xА1 - первый секретный ключ пользователя А, 1<xA1<2n;хВ1 - первый секретный ключ пользователя В, 1<xВ1<2n и формировании пользователями сети первых открытых ключей путем преобразования двоичных векторов первого секретного ключа и чисел а и р уА1≡ (mоd р),..., уВ1≡ (mod р), где уА1 - первый открытый ключ пользователя А;уВ1 - первый открытый ключ пользователя В, передачи по незащищенному каналу связи первых открытых ключей всем другим пользователям сети и формировании пользователем сети для связи с другим пользователем сети первого общего секретного подключа K1 путем преобразования двоичных векторов своего первого секретного ключа и первого открытого ключа другого пользователя сети KAV1 (mod p);KBA1 (mod p);K1 = KAV1 = KVA1, KАВ1(mod p);KBA1 (mod p);К1=KАВ1=KВА1, where KAB1 - the first shared secret is connected between the users A and B;где KAB1 - первый общий секретный подключ между пользователями А и В;KBA1 - the first shared secret is connected between the users B and A, KBA1 - первый общий секретный подключ между пользователями В и А, characterized in that the network users independently generates a second secret keys xA2, ..., xB2 where xa2 - the second secret key of the user A, 1 <xA2 <2n;hV2 - a second secret key of the user B, 1 <xB2 <2n, forms a second public keys by converting binary vectors and the second secret key of a and p yA2axA2 (mod p), ..., uB2axB2 (mod p), where uA2 - second the public key of the user A, YB2 - the second public key of user B transmits a second public keys over an insecure communication channel to all the other users on the network, formed to communicate with another user of the second shared secret subkey K2 by converting binary vectors his second secret key and a second public key Another netizen KAB2 (mod p);KVA2 (mod p);K2 = KAV2 = KVA2 where KAV2 - the second shared secret is connected between the users A and B;KVA2 - the second shared secret is connected between the users B and A, and to send a message is generated for each session a random binary vector ξ, 1 <ξ <2n, form a binary vector β by adding modulo two bits of random binary vector ξ with bits of binary vector first shared secret subkeys K1, using the binary vector β as the encryption key for seeding a shift register having n bits, and generating a pseudo-random sequence of symbols maximal length 2n-1 to encrypt messages form a binary vector α by modulo-two bits of a random binary vector ξ with bits of binary vector of the second shared secret subkey K2 and transmits it through the communication channel with the encrypted message, and when you receive a message by the network generates a random binary vector ξ by modulo two bits of the received binary vector α with bits of binary vector of the second shared secret subkey K2, and then form a binary vector β by adding modulo two bits of random binary vector ξ with bits of binary vector of the first shared secret subkey K1 and binary vector β lays in the ciphering device is produced using a shift register pseudo-random sequence of characters that is used to decrypt the message. отличающийся тем, что пользователи сети независимо друг от друга генерируют вторые секретные ключи xА2,..., xB2 где хА2 - второй секретный ключ пользователя A, 1<xА2<2n;хВ2 - второй секретный ключ пользователя В, 1<xB2<2n, формируют вторые открытые ключи путем преобразования двоичных векторов второго секретного ключа и чисел а и р yA2axA2(mod p),..., уB2axB2(mod p), где уА2 - второй открытый ключ пользователя А, уВ2 - второй открытый ключ пользователя В, передают вторые открытые ключи по незащищенному каналу связи всем другим пользователям сети, формируют для связи с другим пользователем сети второй общий секретный подключ К2 путем преобразования двоичных векторов своего второго секретного ключа и второго открытого ключа другого пользователя сети КAB2 (mod p);KВА2 (mod p);К2=КАВ2=КВА2, где КАВ2 - второй общий секретный подключ между пользователями А и В;КВА2 - второй общий секретный подключ между пользователями В и А, и для передачи сообщения генерируют для каждого сеанса связи случайный двоичный вектор ξ , 1<ξ <2n, формируют двоичный вектор β путем сложения по модулю два битов случайного двоичного вектора ξ с битами двоичного вектора первого общего секретного подключа K1, используют двоичный вектор β в качестве ключа шифрования для начального заполнения регистра сдвига, имеющего n разрядов и вырабатывающего псевдослучайную последовательность символов максимальной длины 2n-1 для шифрования сообщения, формируют двоичный вектор α путем сложения по модулю два битов случайного двоичного вектора ξ с битами двоичного вектора второго общего секретного подключа К2 и передают его по каналу связи вместе с зашифрованным сообщением, а при приеме сообщения пользователя сети формируют случайный двоичный вектор ξ путем сложения по модулю два битов принимаемого двоичного вектора α с битами двоичного вектора второго общего секретного подключа К2, а затем формируют двоичный вектор β путем сложения по модулю два битов случайного двоичного вектора ξ с битами двоичного вектора первого общего секретного подключа K1 и двоичный вектор β закладывает в шифрующее устройство, вырабатывающее с помощью регистра сдвига псевдослучайную последовательность символов, используемую для дешифрования сообщения.